Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. > Apple maintains that it "takes steps to ensure that personal data is not stored or used by Apple."

> Apple maintains that it "takes steps to ensure that personal data is not stored or used by Apple."

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
34 Indlæg 14 Posters 1 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • zzt@mas.toZ zzt@mas.to

    > Apple maintains that it "takes steps to ensure that personal data is not stored or used by Apple." But as Heise points out, and Apple has said in the terms of service for a few years now, the audio material may be listened to by Apple employees after anonymization.
    >
    >Currently, new feature is opt-in only. When iOS 27 rolls out on Monday, September 14, users will see a prompt that asks users to help improve the chatbot, with an agree or "not now" button.
    >
    >It also admits that data collected may be reviewed by "review personnel." It is unclear if "review personnel" are Apple employees or a third-party company contracted to read conversation transcripts, as it has historically been.

    so alongside all the other surveillance shit in the version, iOS devices aren’t even subtle about how they’ll exfiltrate your voice and data now. bitter lol @ the no option being “not now”

    and of course you can’t fully disable apple intelligence now https://hachyderm.io/@evacide/117276255916296665

    cmdrmoto@hachyderm.ioC This user is from outside of this forum
    cmdrmoto@hachyderm.ioC This user is from outside of this forum
    cmdrmoto@hachyderm.io
    wrote sidst redigeret af
    #2

    @zzt oh, it’s even SO MUCH WORSE :

    https://cupoftea.social/@Erased_Citizen/117276446682733552

    yeah. “connection assist” is gonna exfiltrate even if you think you have a pi-hole. ios 27 will send your data via cell plan.

    3^3 is Big Brother’s favorite number, apparently

    colin@mastodon.colincogle.nameC becomethewaifu@tech.lgbtB 2 Replies Last reply
    0
    • zzt@mas.toZ zzt@mas.to

      > Apple maintains that it "takes steps to ensure that personal data is not stored or used by Apple." But as Heise points out, and Apple has said in the terms of service for a few years now, the audio material may be listened to by Apple employees after anonymization.
      >
      >Currently, new feature is opt-in only. When iOS 27 rolls out on Monday, September 14, users will see a prompt that asks users to help improve the chatbot, with an agree or "not now" button.
      >
      >It also admits that data collected may be reviewed by "review personnel." It is unclear if "review personnel" are Apple employees or a third-party company contracted to read conversation transcripts, as it has historically been.

      so alongside all the other surveillance shit in the version, iOS devices aren’t even subtle about how they’ll exfiltrate your voice and data now. bitter lol @ the no option being “not now”

      and of course you can’t fully disable apple intelligence now https://hachyderm.io/@evacide/117276255916296665

      zzt@mas.toZ This user is from outside of this forum
      zzt@mas.toZ This user is from outside of this forum
      zzt@mas.to
      wrote sidst redigeret af
      #3

      most AI corps pretend not to train on user data. they’re lying, as has been proven repeatedly (most recently with the mathematicians’ codex data getting exfiltrated behind their backs), but they pretend not to

      apple isn’t even pretending, they need your data

      it doesn’t matter to them if someone else consented, or if your data or voice are being handled by someone else’s device, and they aren’t particularly subtle about the opt-in being temporary (“not now”)

      no, it’s not better that apple isn’t lying about it, they’re trying their hardest to normalize surveillance

      zzt@mas.toZ bosconet@ioc.exchangeB 2 Replies Last reply
      0
      • zzt@mas.toZ zzt@mas.to

        most AI corps pretend not to train on user data. they’re lying, as has been proven repeatedly (most recently with the mathematicians’ codex data getting exfiltrated behind their backs), but they pretend not to

        apple isn’t even pretending, they need your data

        it doesn’t matter to them if someone else consented, or if your data or voice are being handled by someone else’s device, and they aren’t particularly subtle about the opt-in being temporary (“not now”)

        no, it’s not better that apple isn’t lying about it, they’re trying their hardest to normalize surveillance

        zzt@mas.toZ This user is from outside of this forum
        zzt@mas.toZ This user is from outside of this forum
        zzt@mas.to
        wrote sidst redigeret af
        #4

        if you really think there’s a way to anonymize this type of data, you’ve never worked with supposedly anonymized data like this

        zzt@mas.toZ 1 Reply Last reply
        0
        • zzt@mas.toZ zzt@mas.to

          > Apple maintains that it "takes steps to ensure that personal data is not stored or used by Apple." But as Heise points out, and Apple has said in the terms of service for a few years now, the audio material may be listened to by Apple employees after anonymization.
          >
          >Currently, new feature is opt-in only. When iOS 27 rolls out on Monday, September 14, users will see a prompt that asks users to help improve the chatbot, with an agree or "not now" button.
          >
          >It also admits that data collected may be reviewed by "review personnel." It is unclear if "review personnel" are Apple employees or a third-party company contracted to read conversation transcripts, as it has historically been.

          so alongside all the other surveillance shit in the version, iOS devices aren’t even subtle about how they’ll exfiltrate your voice and data now. bitter lol @ the no option being “not now”

          and of course you can’t fully disable apple intelligence now https://hachyderm.io/@evacide/117276255916296665

          shnizmuffin@toots.inbutts.lolS This user is from outside of this forum
          shnizmuffin@toots.inbutts.lolS This user is from outside of this forum
          shnizmuffin@toots.inbutts.lol
          wrote sidst redigeret af
          #5

          @zzt "yes" or "yes but later" is the sort of thing that should get someone [ reacted ].

          tael@yiff.lifeT 1 Reply Last reply
          0
          • zzt@mas.toZ zzt@mas.to

            if you really think there’s a way to anonymize this type of data, you’ve never worked with supposedly anonymized data like this

            zzt@mas.toZ This user is from outside of this forum
            zzt@mas.toZ This user is from outside of this forum
            zzt@mas.to
            wrote sidst redigeret af
            #6

            so the new iOS has data exfiltration in apple intelligence, always-on audio recording, photos that can be permanently correlated with your specific device, and a connection assist feature (which I’m assuming is enabled by default) that breaks all of your attempts to intentionally filter what’s coming in on your connection

            have I missed any forms of surveillance? who is all this shit for?

            zzt@mas.toZ fivetonsflax@tilde.zoneF 2 Replies Last reply
            0
            • zzt@mas.toZ zzt@mas.to

              so the new iOS has data exfiltration in apple intelligence, always-on audio recording, photos that can be permanently correlated with your specific device, and a connection assist feature (which I’m assuming is enabled by default) that breaks all of your attempts to intentionally filter what’s coming in on your connection

              have I missed any forms of surveillance? who is all this shit for?

              zzt@mas.toZ This user is from outside of this forum
              zzt@mas.toZ This user is from outside of this forum
              zzt@mas.to
              wrote sidst redigeret af
              #7

              I’m sure the company that failed to implement anonymous email addresses and a VPN that doesn’t leak your IP is perfectly capable of keeping a constant stream of your personal information, recording of your audio surroundings, and permanent metadata correlating your photos with your device, safe

              cyberquixote@infosec.exchangeC zzt@mas.toZ hipsterelectron@circumstances.runH 3 Replies Last reply
              0
              • zzt@mas.toZ zzt@mas.to

                I’m sure the company that failed to implement anonymous email addresses and a VPN that doesn’t leak your IP is perfectly capable of keeping a constant stream of your personal information, recording of your audio surroundings, and permanent metadata correlating your photos with your device, safe

                cyberquixote@infosec.exchangeC This user is from outside of this forum
                cyberquixote@infosec.exchangeC This user is from outside of this forum
                cyberquixote@infosec.exchange
                wrote sidst redigeret af
                #8

                @zzt Big Tech is the Governments Big Brother

                cyberquixote@infosec.exchangeC 1 Reply Last reply
                0
                • zzt@mas.toZ zzt@mas.to

                  I’m sure the company that failed to implement anonymous email addresses and a VPN that doesn’t leak your IP is perfectly capable of keeping a constant stream of your personal information, recording of your audio surroundings, and permanent metadata correlating your photos with your device, safe

                  zzt@mas.toZ This user is from outside of this forum
                  zzt@mas.toZ This user is from outside of this forum
                  zzt@mas.to
                  wrote sidst redigeret af
                  #9

                  all the infosec boys going “oh apple private cloud is the best, you can’t deny it’s the best way to do this” and the “this” is something that shouldn’t be done

                  it’s also closed infrastructure you can’t actually evaluate from outside of apple so I’m confused why any of them think the whitepapers are anything other than fantasy

                  freyalikesgirls@transfem.socialF 1 Reply Last reply
                  0
                  • zzt@mas.toZ zzt@mas.to

                    all the infosec boys going “oh apple private cloud is the best, you can’t deny it’s the best way to do this” and the “this” is something that shouldn’t be done

                    it’s also closed infrastructure you can’t actually evaluate from outside of apple so I’m confused why any of them think the whitepapers are anything other than fantasy

                    freyalikesgirls@transfem.socialF This user is from outside of this forum
                    freyalikesgirls@transfem.socialF This user is from outside of this forum
                    freyalikesgirls@transfem.social
                    wrote sidst redigeret af
                    #10

                    @zzt@mas.to "private cloud" sounds like peak oxymoron

                    zzt@mas.toZ 1 Reply Last reply
                    0
                    • cyberquixote@infosec.exchangeC cyberquixote@infosec.exchange

                      @zzt Big Tech is the Governments Big Brother

                      cyberquixote@infosec.exchangeC This user is from outside of this forum
                      cyberquixote@infosec.exchangeC This user is from outside of this forum
                      cyberquixote@infosec.exchange
                      wrote sidst redigeret af
                      #11

                      @zzt “look see you don’t gotta give em consent you can lie to em, i do it all the time”

                      1 Reply Last reply
                      0
                      • freyalikesgirls@transfem.socialF freyalikesgirls@transfem.social

                        @zzt@mas.to "private cloud" sounds like peak oxymoron

                        zzt@mas.toZ This user is from outside of this forum
                        zzt@mas.toZ This user is from outside of this forum
                        zzt@mas.to
                        wrote sidst redigeret af
                        #12

                        @freyalikesgirls it’s ridiculous on the face of it

                        like, we trust open source end to end encrypted systems because we can verify our end, and we can verify that the system mathematically doesn’t function unless encryption is happening as described, and we can assume that the other end isn’t mishandling data (or more accurately we can factor that into our threat model: the other side can be compromised, and we can’t necessarily solve that risk entirely technically)

                        we can’t verify any of that for iOS

                        freyalikesgirls@transfem.socialF zzt@mas.toZ 2 Replies Last reply
                        0
                        • zzt@mas.toZ zzt@mas.to

                          @freyalikesgirls it’s ridiculous on the face of it

                          like, we trust open source end to end encrypted systems because we can verify our end, and we can verify that the system mathematically doesn’t function unless encryption is happening as described, and we can assume that the other end isn’t mishandling data (or more accurately we can factor that into our threat model: the other side can be compromised, and we can’t necessarily solve that risk entirely technically)

                          we can’t verify any of that for iOS

                          freyalikesgirls@transfem.socialF This user is from outside of this forum
                          freyalikesgirls@transfem.socialF This user is from outside of this forum
                          freyalikesgirls@transfem.social
                          wrote sidst redigeret af
                          #13

                          @zzt@mas.to i'm so sick of <big asshole tech corpo> and how much they treat everyone like shit

                          1 Reply Last reply
                          0
                          • zzt@mas.toZ zzt@mas.to

                            @freyalikesgirls it’s ridiculous on the face of it

                            like, we trust open source end to end encrypted systems because we can verify our end, and we can verify that the system mathematically doesn’t function unless encryption is happening as described, and we can assume that the other end isn’t mishandling data (or more accurately we can factor that into our threat model: the other side can be compromised, and we can’t necessarily solve that risk entirely technically)

                            we can’t verify any of that for iOS

                            zzt@mas.toZ This user is from outside of this forum
                            zzt@mas.toZ This user is from outside of this forum
                            zzt@mas.to
                            wrote sidst redigeret af
                            #14

                            @freyalikesgirls like, it’s a fair bet that WhatsApp is end to end encrypted and that the features that aren’t Facebook originals are probably as securely encrypted as signal protocol data, because WhatsApp uses a mild variant of the signal protocol

                            it’s also a fair bet that all ends of a WhatsApp chat are having their data exfiltrated by the WhatsApp client, because that’s what Facebook habitually does. that is how they make money.

                            a thing can look like it implements perfectly good encryption and still leak all the data that goes into it

                            freyalikesgirls@transfem.socialF 1 Reply Last reply
                            1
                            0
                            • zzt@mas.toZ zzt@mas.to

                              @freyalikesgirls like, it’s a fair bet that WhatsApp is end to end encrypted and that the features that aren’t Facebook originals are probably as securely encrypted as signal protocol data, because WhatsApp uses a mild variant of the signal protocol

                              it’s also a fair bet that all ends of a WhatsApp chat are having their data exfiltrated by the WhatsApp client, because that’s what Facebook habitually does. that is how they make money.

                              a thing can look like it implements perfectly good encryption and still leak all the data that goes into it

                              freyalikesgirls@transfem.socialF This user is from outside of this forum
                              freyalikesgirls@transfem.socialF This user is from outside of this forum
                              freyalikesgirls@transfem.social
                              wrote sidst redigeret af
                              #15

                              @zzt@mas.to tbh whatsapp doesnt look like shit, i cant see any of whats inside

                              1 Reply Last reply
                              0
                              • cmdrmoto@hachyderm.ioC cmdrmoto@hachyderm.io

                                @zzt oh, it’s even SO MUCH WORSE :

                                https://cupoftea.social/@Erased_Citizen/117276446682733552

                                yeah. “connection assist” is gonna exfiltrate even if you think you have a pi-hole. ios 27 will send your data via cell plan.

                                3^3 is Big Brother’s favorite number, apparently

                                colin@mastodon.colincogle.nameC This user is from outside of this forum
                                colin@mastodon.colincogle.nameC This user is from outside of this forum
                                colin@mastodon.colincogle.name
                                wrote sidst redigeret af
                                #16

                                @cmdrmoto @zzt That’s not a new feature. It used to be called Wi-Fi Assist. I don’t know what changed in iOS 27 besides the name.

                                I use NextDNS, and they have a configuration profile that applies their DoH servers at the OS level regardless of which network I’m on. Still, I’m planning on switching to Pi-hole when my subscription expires, so this is good to know.

                                1 Reply Last reply
                                0
                                • cmdrmoto@hachyderm.ioC cmdrmoto@hachyderm.io

                                  @zzt oh, it’s even SO MUCH WORSE :

                                  https://cupoftea.social/@Erased_Citizen/117276446682733552

                                  yeah. “connection assist” is gonna exfiltrate even if you think you have a pi-hole. ios 27 will send your data via cell plan.

                                  3^3 is Big Brother’s favorite number, apparently

                                  becomethewaifu@tech.lgbtB This user is from outside of this forum
                                  becomethewaifu@tech.lgbtB This user is from outside of this forum
                                  becomethewaifu@tech.lgbt
                                  wrote sidst redigeret af
                                  #17

                                  @cmdrmoto @zzt JFC, doing it that way is completely unreasonable. Android's implementation is somewhat more reasonable, if a bit more "brute-force," switching entirely to cellular when the network quality drops too low, rather than actively working around the network administrator's controls while still using that network... (And AFAIK it goes off radio alone?)

                                  Though I wonder exactly how pi-hole implements the blocking? Is it dropped requests, bogus nxdomain, or some other response? Because how intentionally malicious that "feature" is depends on how reasonable it is to see those blocks as network-level errors.

                                  If it's responding with spoofed valid responses like nxdomain, or an empty "no error" response, there is no legitimate reason to query another resolver outside of bypassing dns-level blocking.

                                  But if it's implementing the blocking by refusing queries for those domains rather than spoofing a 'valid' response, I could see a reasonable device interpreting it that as a broken resolver.

                                  tsrberry@ravenation.clubT h@is-a.catinsi.deH 2 Replies Last reply
                                  0
                                  • becomethewaifu@tech.lgbtB becomethewaifu@tech.lgbt

                                    @cmdrmoto @zzt JFC, doing it that way is completely unreasonable. Android's implementation is somewhat more reasonable, if a bit more "brute-force," switching entirely to cellular when the network quality drops too low, rather than actively working around the network administrator's controls while still using that network... (And AFAIK it goes off radio alone?)

                                    Though I wonder exactly how pi-hole implements the blocking? Is it dropped requests, bogus nxdomain, or some other response? Because how intentionally malicious that "feature" is depends on how reasonable it is to see those blocks as network-level errors.

                                    If it's responding with spoofed valid responses like nxdomain, or an empty "no error" response, there is no legitimate reason to query another resolver outside of bypassing dns-level blocking.

                                    But if it's implementing the blocking by refusing queries for those domains rather than spoofing a 'valid' response, I could see a reasonable device interpreting it that as a broken resolver.

                                    tsrberry@ravenation.clubT This user is from outside of this forum
                                    tsrberry@ravenation.clubT This user is from outside of this forum
                                    tsrberry@ravenation.club
                                    wrote sidst redigeret af
                                    #18

                                    @becomethewaifu @cmdrmoto @zzt Responses by pihole are configurable. Iirc the default is nxdomain, but it could also reply with 0.0.0.0

                                    tsrberry@ravenation.clubT becomethewaifu@tech.lgbtB 2 Replies Last reply
                                    0
                                    • tsrberry@ravenation.clubT tsrberry@ravenation.club

                                      @becomethewaifu @cmdrmoto @zzt Responses by pihole are configurable. Iirc the default is nxdomain, but it could also reply with 0.0.0.0

                                      tsrberry@ravenation.clubT This user is from outside of this forum
                                      tsrberry@ravenation.clubT This user is from outside of this forum
                                      tsrberry@ravenation.club
                                      wrote sidst redigeret af
                                      #19

                                      @becomethewaifu @cmdrmoto @zzt Nvm, it answers with 0.0.0.0 by default.

                                      1 Reply Last reply
                                      0
                                      • shnizmuffin@toots.inbutts.lolS shnizmuffin@toots.inbutts.lol

                                        @zzt "yes" or "yes but later" is the sort of thing that should get someone [ reacted ].

                                        tael@yiff.lifeT This user is from outside of this forum
                                        tael@yiff.lifeT This user is from outside of this forum
                                        tael@yiff.life
                                        wrote sidst redigeret af
                                        #20

                                        @shnizmuffin @zzt this is Mastodon, if you need to redact it, you should move to a new instance lol (and you're the instance owner so I hope you're allowed to say it!)

                                        it should get you dragged out in the street and shot

                                        shnizmuffin@toots.inbutts.lolS 1 Reply Last reply
                                        0
                                        • tsrberry@ravenation.clubT tsrberry@ravenation.club

                                          @becomethewaifu @cmdrmoto @zzt Responses by pihole are configurable. Iirc the default is nxdomain, but it could also reply with 0.0.0.0

                                          becomethewaifu@tech.lgbtB This user is from outside of this forum
                                          becomethewaifu@tech.lgbtB This user is from outside of this forum
                                          becomethewaifu@tech.lgbt
                                          wrote sidst redigeret af
                                          #21

                                          @tsrberry @cmdrmoto @zzt Since 0.0.0.0 isn't a valid IP for DNS, I could reasonably see that being interpreted as "this resolver is doing something dumb" rather than "this record was intentionally blocked." I'd try nxdomain or NODATA, and if it's doing this for those? It's either vibecoded to retry-on-cellular for any DNS error, not just plausibly "crap network" ones, or it was written to intentionally subvert network administrator control...

                                          Though after thinking about it a bit, it could also be looking for dnssec signatures? pi-hole necessarily has to break those to block things after all. I'd have to sniff every DNS request the phone makes to be sure (not particularly difficult with my network, but I don't have an iphone to actually do that with...) but it's entirely plausible for apple's "security focus" to forget that network administrators intentionally break it sometimes.

                                          1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper